A practical and provably secure coalition-resistant group signature scheme

Giuseppe Ateniese, Jan Camenisch, Marc Joye, Gene Tsudik

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

641 Scopus citations

Abstract

A group signature scheme allows a group member to sign messages anonymously on behalf of the group. However, in the case of a dispute, the identity of a signature’s originator can be revealed (only) by a designated entity. The interactive counterparts of group signatures are identity escrow schemes or group identification scheme with revocable anonymity. This work introduces a new provably secure group signature and a companion identity escrow scheme that are significantly more efficient than the state of the art. In its interactive, identity escrow form, our scheme is proven secure and coalition-resistant under the strong RSA and the decisional Diffie-Hellman assumptions. The security of the noninteractive variant, i.e., the group signature scheme, relies additionally on the Fiat-Shamir heuristic (also known as the random oracle model).

Original languageEnglish
Title of host publicationAdvances in Cryptology - CRYPTO 2000 - 20th Annual International Cryptology Conference, Proceedings
EditorsMihir Bellare
Pages255-270
Number of pages16
DOIs
StatePublished - 2000
Event20th Annual International Cryptology Conference, CRYPTO 2000 - Santa Barbara, United States
Duration: 20 Aug 200024 Aug 2000

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume1880
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference20th Annual International Cryptology Conference, CRYPTO 2000
Country/TerritoryUnited States
CitySanta Barbara
Period20/08/0024/08/00

Keywords

  • Coalitionresistance
  • Group signature schemes
  • Identity escrow
  • Provable security
  • Revocable anonymity
  • Strong RSA assumption

Fingerprint

Dive into the research topics of 'A practical and provably secure coalition-resistant group signature scheme'. Together they form a unique fingerprint.

Cite this